Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2612▼ 295 respecto a la semana anterior
Críticas / altas1346▲ 82 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.35% | — | ContinuwuityAIConduitAIGrapevineAITuwunelAI | 2/2/2026 | 17/6/2026 | continuwuity is a Matrix homeserver written in Rust. This vulnerability allows an attacker with a malicious remote server to cause the local server to sign an arbitrary event upon user interaction. Upon a user account leaving a room (rejecting an invite), joining a room or knocking on a room, the victim server may ask… | |
| Aplazada | Crítica (9.9) | 0.59% | — | ConduitAIContinuwuityAIGrapevineAITuwunelAI | 23/12/2025 | 17/6/2026 | Conduit is a chat server powered by Matrix. A vulnerability that affects a number of Conduit-derived homeservers allows a remote, unauthenticated attacker to force the target server to cryptographically sign arbitrary membership events. Affected products include Conduit prior to version 0.10.10, continuwuity prior to… | |
| Analizada | Media (6.1) | 0.28% | — | Aimeos Grapesjs CMS | 2/12/2025 | 17/6/2026 | The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components. Prior to 2021.10.8, 2022.10.8, 2023.10.8, 2024.10.8, and 2025.10.8, Javascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. This… | |
| Aplazada | Alta (8.8) | 0.42% | — | GrapesjsAI | 2/12/2025 | 17/6/2026 | Summary Arbitrary files can be uploaded via the GrapesJS Builder, as the types of files that can be uploaded are not restricted. ImpactIf the media folder is not restricted from running files this can lead to a remote code execution. | |
| Aplazada | Alta (8.8) | 0.24% | — | GradleAINet.rubygrapefruit Native-platformAI | 25/2/2025 | 17/6/2026 | Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. On Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. This library initialization could be vulnerable to a local… | |
| Modificada | Alta (8.8) | 0.27% | — | Marketingrapel Mkrapel Regiones Y Ciudades DE Chile Para WC | 18/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Marketing Rapel MkRapel Regiones y Ciudades de Chile para WC.This issue affects MkRapel Regiones y Ciudades de Chile para WC: from n/a through 4.3.0. | |
| Modificada | Media (6.1) | 0.77% | — | Grapesjs | 25/7/2022 | 17/6/2026 | The package grapesjs before 0.19.5 are vulnerable to Cross-site Scripting (XSS) due to an improper sanitization of the class name in Selector Manager. | |
| Modificada | Media (6.1) | 1.4% | — | Ruby-grape Grape | 5/7/2018 | 17/6/2026 | ruby-grape ruby gem suffers from a cross-site scripting (XSS) vulnerability via "format" parameter. | |
| Modificada | Alta (7.5) | 3.7% | — | Erik Michaels-ober Multi XMLGrape Project Grape | 25/4/2013 | 16/6/2026 | multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity… | |
| Modificada | Media (4.3) | 1.3% | — | Grapecity Data Dynamics Reports | 10/4/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the DataDynamics.Reports.Web class library in GrapeCity Data Dynamics Reports before 1.6.2084.14 allow remote attackers to inject arbitrary web script or HTML via (1) the reportName or (2) uniqueId parameter to CoreViewerInit.js, or the (3) uniqueId or (4)… | |
| Modificada | Alta (7.5) | 39% | — | Quate Grape WEB Statistics | 25/4/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/functions.php in Quate Grape Web Statistics 0.2a allows remote attackers to execute arbitrary PHP code via a URL in the location parameter. |